Workspace
/
Findings
AU

Findings

Convert AI governance risk flags into audit-style findings using condition, criteria, cause, risk/effect, and recommendation.

Total Findings
5
High Risk Findings
2
Medium Risk Findings
3
Draft Findings
2
Ready for Report
3

OpenAI API Usage Increased Without Complete Approval Evidence

HighReady for Report
Tool/Provider: OpenAI API
Department: Marketing
Condition

OpenAI API usage increased 39% from the prior month, but approval evidence and usage review documentation were only partially available.

Criteria

AI and cloud/API usage should have documented approval, assigned ownership, business purpose, and periodic review when costs or usage materially increase.

Cause

The department expanded API usage before updating governance documentation and review evidence.

Risk/Effect

Increased AI/API usage without complete approval evidence may result in unreviewed costs, unclear accountability, and weak audit evidence over AI tool governance.

Recommendation

Management should document approval evidence, confirm the business purpose, review the usage increase, and assign periodic monitoring responsibility.

Claude API Lacks Assigned Business Owner

HighReady for Report
Tool/Provider: Claude API
Department: IT
Condition

Claude API is active for engineering sandbox and internal testing, but no accountable business owner is documented.

Criteria

AI tools and API services should have an assigned business owner responsible for usage, approval, documentation, and ongoing review.

Cause

The tool appears to have been adopted for testing before ownership responsibilities were formally assigned.

Risk/Effect

Lack of ownership may delay review, approval, cost monitoring, and remediation of AI governance issues.

Recommendation

Management should assign a business owner, document the tool purpose, and confirm approval and monitoring responsibilities.

Midjourney Has No Documented Business Purpose

MediumDraft
Tool/Provider: Midjourney
Department: Creative
Condition

Midjourney is listed as active, but the business purpose and approval evidence are not documented.

Criteria

AI tools should have a documented business purpose, approved use case, and evidence supporting authorized use.

Cause

Creative AI tools may have been adopted informally before the inventory and approval process was completed.

Risk/Effect

Tools without documented purpose may create unnecessary cost, duplicate functionality, or unclear policy exceptions.

Recommendation

Management should document the approved use case, confirm ownership, and determine whether the tool should remain active.

Duplicate AI Capability Identified Across Productivity Tools

MediumManagement Review
Tool/Provider: Gemini Workspace / Microsoft Copilot
Department: Operations
Condition

Gemini Workspace and Microsoft Copilot appear to provide overlapping AI productivity capabilities for the same department.

Criteria

AI tool usage should be reviewed for duplication, cost efficiency, business need, and alignment with approved enterprise tools.

Cause

Departments may have adopted separate AI tools without a centralized review of overlapping functionality.

Risk/Effect

Duplicate AI tools may increase cost, fragment governance oversight, and reduce consistency in approved AI usage.

Recommendation

Management should compare the tools, evaluate business need, and determine whether consolidation or additional approval is required.

AWS Bedrock Policy Exception Requires Management Review

MediumDraft
Tool/Provider: AWS Bedrock
Department: Data Analytics
Condition

AWS Bedrock usage was identified with a policy exception and partial supporting evidence.

Criteria

Policy exceptions should be documented, reviewed, approved, and monitored by the appropriate management owner.

Cause

Model testing activity may have moved forward before the exception process was fully documented.

Risk/Effect

Unreviewed policy exceptions may create inconsistent governance, unclear risk acceptance, and weak evidence for management reporting.

Recommendation

Management should complete the policy exception review, document approval, and define monitoring requirements.

Findings Preparation Notes

2 of 5 steps completed

  • Confirm finding language is supported by evidenceDone
  • Validate severity ratingsDone
  • Confirm management owner for each findingPending
  • Prepare findings for export reportPending
  • Mark final findings as ready for reportPending

Sample data only. Built as an independent AI governance workflow and reporting prototype. This demo does not provide legal advice, compliance certification, audit assurance, or regulatory assurance.